CVE-2026-69112 – Hugging Face Accelerate
CVSS 7.1
IMPORTANT
Zero Day – Immediate Deployment
“A malicious checkpoint can reach beyond its intended files and expose sensitive data on the host.”
Hugging Face Accelerate through version 1.14.0 is affected by a path traversal vulnerability in checkpoint-loading functions. Crafted checkpoint indexes can use relative or absolute paths to access arbitrary files, while malicious shard references can also cause indefinite blocking and denial of service. CVE-2026-69112 has a CVSS score of 7.1, High severity.
Public proof-of-concept information is available for this vulnerability.
Key Details
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-22
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.